PROFESSIONAL-SECURITY-OPERATIONS-ENGINEER · Question #25
You are threat hunting for an advanced threat group known for targeted, novel attacks by deploying campaign-specific infrastructure. You want to develop detections based on the threat group's…
The correct answer is D. Search for the threat actor in Google Threat Intelligence, review the threat actor's tactics. The most effective approach is to search for the threat actor in Google Threat Intelligence, review their tactics, techniques, and procedures (TTPs), and design detections based on those TTPs in Google SecOps. Since advanced groups often use novel, campaign-specific…
Question
You are threat hunting for an advanced threat group known for targeted, novel attacks by deploying campaign-specific infrastructure. You want to develop detections based on the threat group's behaviors so you can effectively detect whether the threat group has attacked your organization. What should you do?
Options
- AIdentify exposed technologies and products used by your organization, and develop detections to
- BFind intelligence reports in Google Threat Intelligence that relate to the threat actor, identify their
- CSearch for the threat actor in Google Threat Intelligence, export the IOCs associated with the
- DSearch for the threat actor in Google Threat Intelligence, review the threat actor's tactics,
How the community answered
(43 responses)- A14% (6)
- B7% (3)
- C5% (2)
- D74% (32)
Explanation
The most effective approach is to search for the threat actor in Google Threat Intelligence, review their tactics, techniques, and procedures (TTPs), and design detections based on those TTPs in Google SecOps. Since advanced groups often use novel, campaign-specific infrastructure, IOC- based detection is insufficient. TTP-based detection captures the underlying attacker behaviors, increasing resilience against evolving tactics.
Topics
Community Discussion
No community discussion yet for this question.